A password reset is not enough if the attacker already captured the recovery key. This campaign shifts the weak point from the chat app itself to the account recovery path, which can keep access alive across devices and after the user thinks they have closed the door.
SSU and the FBI say Russian intelligence used fake support SMS to steal messaging credentials from officials, military personnel, politicians, activists, and personal accounts in Ukraine, Europe, and the U.S. The FBI also says the same actor set is going after backup recovery keys in commercial messaging apps, which makes the access harder to kick out than a stolen password alone.
That changes containment. For Telegram, Signal, and similar accounts, the question is no longer only who got in, but what recovery material they took with them and whether that lets them return later.